When authenticating OAuth clients using HTTP Basic Auth, an empty password should be treated as…
When authenticating OAuth clients using HTTP Basic Auth, an empty password should be treated as…: a task in LegoFlow-SWE (Harbor dataset). This causes issues with public clients (clients without a client secret). The Rust openid crate and Reqwest's basic auth function encode an empty/None client…
The task
This causes issues with public clients (clients without a client secret). The Rust `openid` crate and Reqwest's `basic_auth` function encode an empty/None client secret as `username:` in the Authorization header, which is a valid encoding. When oxide-auth receives this, it should recognize that an empty password…
Part of Lego-X/LegoFlow-SWE.